Junglewise Threat Intelligence

CVE-2004-1464: Cisco IOS Denial-of-Service Vulnerability

CVE-2004-1464 · Severity: critical · CVSS 5.9 · Exploited in the wild · Published 2023-05-19

Technologies: Cisco IOS, Cisco IOS XE, Cisco IOS XR. Vendors: Cisco.

Executive brief

Cisco IOS contains a denial-of-service vulnerability where a crafted TCP connection to the Telnet or reverse Telnet port can exhaust virtual terminal (VTY) connections. This can block legitimate administrative access via Telnet, RSH, SSH, and HTTP.

Affected products

  • Cisco IOS 12.2(15) and earlier

Timeline

  • 2004-08-27: disclosed: Initial vendor advisory date based on reference URL
  • 2023-05-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats